<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2009://3/tag:ask-leo.com,2008://3.3262-</id>
  <updated>2009-11-18T17:50:41Z</updated>
  <title>Comments for Can I recover my MSN Hotmail password rather than reset it?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.25</generator>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31151</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31151" />
    <title>Comment from Shahid on 2009-05-03</title>
    <author>
      <name>Shahid</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Where i see my password of my hotmail account<br />
<div class="leocomment">As outlined in the article you just commented on: you cannot.<br />
<div class="leocommentsig">- Leo<br /><span class="leocommentdate">04-May-2009</span></div></div></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-05-03T15:46:03Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31150</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31150" />
    <title>Comment from ammir@msn.com on 2009-01-25</title>
    <author>
      <name>ammir@msn.com</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>So if a site sends you a new password, and they have only an encrypted form, then your computer has to know what algorithm to use to duplicate the encryption. How does it find that out? Also, does your computer store the password or the encryption when you tell it to remember your password? If your computer stores the password, is there any way to access it?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-01-25T22:42:11Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31149</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31149" />
    <title>Comment from Leo A. Notenboom on 2008-01-11</title>
    <author>
      <name>Leo A. Notenboom</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1</p>

<p>Well, it most certainly IS possible. Unfortunately I don't<br />
have a clear metaphor against which to draw a comparison.<br />
The concept of one-way hashes are nothing new, really, and<br />
the foundation of modern cryptography. No, it's nowhere near<br />
as simple as just adding something you could later subtract.<br />
It's quite complex mathmatics.</p>

<p>(In fact the PGP signature below this message is another<br />
example of hashes being used :-).</p>

<p>Thanks,</p>

<p>Leo</p>

<p><br />
-----BEGIN PGP SIGNATURE-----<br />
Version: GnuPG v1.4.7 (MingW32)</p>

<p>iD8DBQFHh6w7CMEe9B/8oqERApdzAJ41AfzyeCqU2mo7ZfQtA1D94wuz4wCffAbM<br />
ARNHwGc/FieBU2XlORHtdqU=<br />
=pwr6<br />
-----END PGP SIGNATURE-----</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-01-11T17:49:19Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31148</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31148" />
    <title>Comment from Ronny on 2008-01-10</title>
    <author>
      <name>Ronny</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I don't understand how it is possible for a computer to run a password through a formula to convert it to something else but not know how to reverse it; assuming, of course, that you know the original formula.</p>

<p>If I do something simple like adding 7 to each ASCII value, I just subtract 7 to reverse it. I know the conversion is more complex than that. That just makes the reversing more complex, not impossible. Right?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-01-11T00:03:38Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31147</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31147" />
    <title>Comment from Ken B on 2008-01-10</title>
    <author>
      <name>Ken B</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Chuck:<br />
> your computer has to know what algorithm to use<br />
> to duplicate the encryption</p>

<p>Your computer doesn't need to know anything about the site's encryption methods.  Your computer sends the password itself to the other computer, and the other computer then encrypts your password to see if it matches the saved encrypted version.  </p>

<p>(Hopefully, your computer and the other computer are using a secure means of communication, such as https rather than http.)</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-01-10T16:40:53Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31146</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31146" />
    <title>Comment from Simon on 2008-01-10</title>
    <author>
      <name>Simon</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>>It means that in the example above there's no way given <br />
>the "187483f86b7c516e35dc52aa30797f44e73ec734" to <br />
>figure out that the password you used to create it was "Pass!werd".</p>

<p>Not quite true. There's no direct way, certainly; but with passwords below a certain length, there is an indirect way of going 'backward': rainbow tables.</p>

<p>These are basically a vast table of precomputed hash values for every possible password, from aaaaaaa upwards.  The original computation of these hash tables is obviously ridiculously time intensive, but it only needs to be done once; after that, getting a password from a hash is just a matter of comparing the hash values until you get a match, which is a quite quick task.  And, as you'd expect, rainbow tables for the most common hashes (MD5 etc.) are freely available on the internet (bittorrent etc.).</p>

<p>Obviously, though, as password length increases, the length of rainbow tables increases exponentially (Formula: no. of allowable characters ^ length).  Rainbow tables for up to 7 character lowercase alphanumeric passwords are under a gigabyte, meaning the whole table can be stored in RAM on a modern computer; making finding a password a matter of seconds.  Add in the 33 non-alphanumeric characters, though, and the size shoots up to 8 GB -- for 7 characters or under passwords.  Adding in an eighth character, or allowing uppercase characters, makes the size shoot up to the hundreds or thousands of Gigabytes -- time-consuming, but definitely not impossible for someone who has stolen the database and can run the algorithm at their leisure.</p>

<p>A nine character non-alphanumeric password like "Pass!werd" is thus probably effectively immune from this effect, purely for reasons of time.  But only today!  Just as the amount of time it takes to use this technique increases exponentially with password length, so does the power of computer hardware with time increase exponentially -- Moore's law.  Give it another half decade, and hardware will probably be powerful enough for a 9 character password to be viably cracked with rainbow tables.</p>

<p>The most common use of Rainbow tables is thus against Windows' LMHash; which versions of Windows prior to Vista used by default to hash login passwords.  The thing about LMHash is that it splits passwords under 14 characters into two 7-character-long strings (and converted everything to lowercase); making it very easy to be crack using 7-character rainbow tables.</p>

<p>There are good defenses against rainbow tables.  For the user, use long passwords (>8 characters), and avoid dictionary words (even a seven character rainbow table will probably have the hashes of all dictaionary words included; compared to the rest of the database the size they take up woud be minimal).</p>

<p>For the system administrator, there is a technique called 'salting' -- prepend a sequence of characters to every password, hash that, and store the sequence in plaintext; prepending it to every password that user tries to enter.  E.g. User: AskLeo, Password: shortpwd, Randomly-generated-string: 64795138.  The system would hash "64795138shortpwd", and store "AskLeo", "64795138", and the hash in its database.  Any time AskLeo tries to log in, the system would add "64795138" on to the beginning of the password you enter, hash that, and see if that hash matches the stored one.  If the string is long enough, even though the cracker knows the string they would have to make a new Rainbow table for each user (For AskLeo, 64795138aaaaaaa to 64795138zzzzzzz; for someone else, maybe 13576824aaaaaaa  to 13576824zzzzzzz); which destroys the whole point of using rainbow tables.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-01-10T12:53:46Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31145</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31145" />
    <title>Comment from Chuck Arnett on 2008-01-09</title>
    <author>
      <name>Chuck Arnett</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>So if a site sends you a new password, and they have only an encrypted form, then your computer has to know what algorithm to use to duplicate the encryption.  How does it find that out?  Also, does your computer store the password or the encryption when you tell it to remember your password?  If your computer stores the password, is there any way to access it?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-01-09T22:16:37Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2008://3.3262-comment:31144</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2008://3.3262" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html#c31144" />
    <title>Comment from Just J on 2008-01-09</title>
    <author>
      <name>Just J</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Message to Arben:  You have clearly NOT read the article (or failed to understand it).</p>

<p>Nice example of password encryption though Leo!</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_recover_my_msn_hotmail_password_rather_than_reset_it.html">Can I recover my MSN Hotmail password rather than reset it?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2008</a>.</p>
    </content>
    <published>2008-01-09T21:40:01Z</published>
  </entry>

</feed>
